Skip to main content
Glama

buildx_build

Build container images with BuildKit, supporting multi-platform builds, cache import/export, SBOM/provenance attestations, build secrets, and multi-stage targets. Runs with plain progress output for captured logs.

Instructions

Build an image with BuildKit via docker buildx build.

Replaces the legacy image_build tool when you need any of: multi-platform output (platforms), modern cache export (cache_from/cache_to), SBOM or provenance attestations, build secrets, or multi-stage builds with target. Always runs with --progress=plain so output is captured rather than redrawn on a TTY. With no local buildx plugin and an ssh:// target, the build runs on that host: a local context directory is copied there honouring .dockerignore, as are file, build_contexts and secret paths. Raises RuntimeError in that case for output/cache_to with a filesystem dest=, cache_from with a local src=, or any ssh= — each would resolve on the remote machine, losing the output or silently changing the build.

args: context - Build context: a filesystem path or Git/HTTP URL (verbatim; no ~/glob expansion). The - stdin-tarball form is NOT supported (stdin isn't forwarded — it'd block on the server's own stdin); serve a pre-packed tarball over HTTP instead. Copied to the target host when it names a local directory and there is no local plugin. tags - Image references to apply (-t, repeatable) platforms - Target platforms, e.g. ["linux/amd64", "linux/arm64"] file - Dockerfile path. A relative path resolves against this server's working directory (buildx's own rule), NOT against context — pass e.g. "ctx/Dockerfile" for a Dockerfile inside the context directory "ctx". build_args - Build-time variables (each becomes --build-arg KEY=VALUE) build_contexts - Additional named build contexts (e.g. {"deps": "./vendor"}) labels - Labels to set on the resulting image (each becomes --label KEY=VALUE) annotations - OCI manifest annotations (passed verbatim, repeatable) target - Target build stage to stop at push - Push the result to the registry (mutually exclusive with load) load - Load the result into the local image store (single-platform builds only) output - Custom --output specs (e.g. ["type=tar,dest=out.tar"]). A filesystem dest= is refused when the build has to run on a remote host; dest=- (stdout) is fine. no_cache - Do not use cache when building no_cache_filter - Stage names to exclude from caching pull - Always attempt to pull a newer version of each base image cache_from - Cache import specs, e.g. ["type=registry,ref=user/img:cache"] cache_to - Cache export specs builder - Override the active builder sbom - Shorthand for --attest=type=sbom; pass "true" or a config string provenance - Shorthand for --attest=type=provenance; pass "true", "false", or a config string attest - Custom attestation specs (repeatable) secret - Secret specs (e.g. ["id=npmrc,src=/home/user/.npmrc"] or ["id=npmrc,env=NPM_TOKEN"]). ~ in src= is NOT expanded (by this tool or the CLI) — use an absolute path. ssh - SSH agent socket/key specs (e.g. ["default"], using $SSH_AUTH_SOCK). Refused when the build has to run on a remote host: the socket read would be that host's. timeout_seconds - Subprocess timeout (default 1800s) returns: dict - {"returncode": int, "stdout": str, "stderr": str, "truncated": bool}

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sshNo
fileNo
loadNo
pullNo
pushNo
sbomNo
tagsNo
attestNo
labelsNo
outputNo
secretNo
targetNo
builderNo
contextYes
cache_toNo
no_cacheNo
platformsNo
build_argsNo
cache_fromNo
provenanceNo
annotationsNo
build_contextsNo
no_cache_filterNo
timeout_secondsNo
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the sparse annotations (readOnlyHint=false, destructiveHint=false), the description discloses substantial behavioral traits: output capture with `--progress=plain`, remote build behavior (context copying via `.dockerignore`), rejects for certain `output`/`cache_to`/`cache_from`/`ssh` combinations that would resolve on the remote machine, and the fact that stdin is not forwarded. These specifics far exceed the annotations and are crucial for safe invocation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but every sentence adds value. It starts with a one-line purpose, then a usage paragraph, then a per-parameter breakdown with examples and restrictions. For 24 parameters, this level of detail is appropriate and well-organized into a readable list. No filler or redundant content exists.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description explicitly states the return shape as `{"returncode": int, "stdout": str, "stderr": str, "truncated": bool}`. It covers remote-host fallback behavior, unsupported stdin, file path resolution rules, and timeout default. For a tool with 24 parameters and no structured output definition, this description is exceptionally complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Even though schema description coverage is technically 0% (no descriptions inside the schema), the tool description itself provides rich semantics for every parameter. It gives examples (e.g., `platforms` as `["linux/amd64", "linux/arm64"]`), constraints (e.g., `file` relative to server working directory, not `context`), and edge cases (e.g., `~` not expanded in `secret` `src=`). This far surpasses what the bare schema provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description begins with a specific verb and resource: 'Build an image with BuildKit via `docker buildx build`.' It clearly distinguishes itself from the legacy `image_build` tool by enumerating the advanced capabilities (multi-platform, cache export, attestations, secrets, multi-stage targets), leaving no ambiguity about its scope.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use this tool: 'Replaces the legacy `image_build` tool when you need any of...' and also provides a when-not-to-use example (stdin tarball unsupported). It also documents that it always runs with `--progress=plain` and warns about remote-host restrictions, giving the agent clear decision-making context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/L337-org/docker-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server